跳到正文
dsh-market 浏览插件 GitHub EN

Baiiduu/dsh-semgrep-sast#semgrep-sast

面向 DeepSeek Harness 的工作区内 Semgrep SAST 工具,提供托管 Windows x64 运行时、结构化有界结果、取消与超时控制,以及经用户批准的沙箱权限升级。npm 包名为 @aaub-software/dsh-semgrep-sast。

Star 数 ★ 1 分类 安全与权限 收录于 2026-09-06 npm @aaub-software/dsh-semgrep-sast

安装

在 DeepSeek Harness 里通过 dsh-market 安装

dsh plugin --profile web add dshmarket

或使用命令行

dsh plugin --profile web add @aaub-software/dsh-semgrep-sast

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络。请先审阅源码,并尽量锁定 commit(github:owner/repo#sha)。

README

该插件的 README 只有英文版本。

@aaub-software/dsh-semgrep-sast is a Cordis bundle that registers the model-facing semgrep_scan tool in DeepSeek Harness.

The default managed runtime supports Windows x64 and includes CPython 3.14.7 and Semgrep 1.175.0. Users do not need to install Python or Semgrep separately.

Install

DeepSeek Harness and Node.js 24 or newer are required. Install the bundle into the profile you use, for example:

dsh plugin --profile web add @aaub-software/dsh-semgrep-sast

Restart the profile after installation. The agent will then see the semgrep_scan tool.

Behavior and safety

  • Scans only workspace-relative files and directories.
  • Rejects paths and resolved symlinks that escape the active workspace.
  • Uses the Semgrep Registry p/default ruleset.
  • Does not expose autofix and disables Semgrep metrics.
  • Redirects Semgrep cache, settings, configuration, and logs to the temporary scan environment.
  • Supports Harness cancellation, timeout, process-tree termination, bounded subprocess output, and bounded model-facing findings.
  • Returns structured findings for contextual review; a rule match is not by itself a confirmed vulnerability.

Model-facing result

Version 0.2 returns the public ssc-sast/v1 contract from @aaub-software/dsh-sast-contract. The Agent receives normalized JSON rather than native Semgrep output:

{
  "schemaVersion": "ssc-sast/v1",
  "status": "completed",
  "scanner": {
    "name": "semgrep",
    "version": "1.175.0",
    "configuration": "p/default"
  },
  "scannedPaths": ["src/server.js"],
  "findings": [],
  "diagnostics": [],
  "summary": {
    "totalFindings": 0,
    "returnedFindings": 0,
    "truncated": false,
    "durationMs": 125
  }
}

Each finding contains a stable ID, scanner attribution, normalized rule metadata, an exact workspace-relative location, and bounded evidence. Semgrep matched code and metavariables are exposed as semgrep.matched-code and semgrep.metavariables evidence when present. CWE, OWASP, references, and fingerprints are retained only when Semgrep emitted them; the adapter does not guess missing metadata. Diagnostics remain separate from security findings so an incomplete scan cannot be mistaken for a clean scan.

On Windows, Semgrep Core cannot open the system certificate store inside the current Harness ACL sandbox. A restricted first call does not start the scan. Instead, it returns the standard permission-escalation hint. The model may retry the same scan with sandbox_permissions: "danger-full-access" and a concise justification; Harness asks the user for approval before execution.

The default ruleset is obtained from the Semgrep Registry at scan time and may require network access. Registry rules are not redistributed by this package.

Documentation and source

See the repository documentation for the complete English and Chinese guide, configuration reference, security controls, development instructions, and third-party license information.

Source: Baiiduu/dsh-semgrep-sast

内容来自项目 README(GitHub)↗

评论

评论存放在 GitHub Discussions。用 GitHub 账号登录后可发表评论或点表情。